Hacking, AppSec, and Bug Bounty newsletter
2017-11-06 | CertStream, Tormoil fixed, and Cyber Operations Tracker
Monday, November 6
Any user with invite capabilities can take-over any account on Discourse [45 upvotes] - $1,024 bounty for this report to Discourse by @mishre.
You can see all the latest and greatest disclosures and bounties on www.hackerone.com/hacktivity
TWEET OF THE DAY
Jdwp exposed to the internet. You’re gonna have a bad time. - @seanmeals
OTHER ARTICLES WE’RE READING
SAVE Act: Securing America’s Voting Equipment Act of 2017. See Sec. 304 “Bug bounty programs”
CertStream – See SSL certs as they're issued in real time
Anime streaming service Crunchyroll hijacked to distribute malware
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
Get this email forwarded to you? Click here to subscribe to the Zero Daily
Finding bugs: Exciting.
Fixing those bugs: Not exciting.